Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h832-96qp-642g

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The addmntent function in the GNU C Library (aka glibc or libc6) 2.13 and earlier does not report an error status for failed attempts to write to the /etc/mtab file, which makes it easier for local users to trigger corruption of this file, as demonstrated by writes from a process with a small RLIMIT_FSIZE value, a different vulnerability than CVE-2010-0296.

The addmntent function in the GNU C Library (aka glibc or libc6) 2.13 and earlier does not report an error status for failed attempts to write to the /etc/mtab file, which makes it easier for local users to trigger corruption of this file, as demonstrated by writes from a process with a small RLIMIT_FSIZE value, a different vulnerability than CVE-2010-0296.

EPSS

Процентиль: 26%
0.00087
Низкий

Связанные уязвимости

ubuntu
больше 14 лет назад

The addmntent function in the GNU C Library (aka glibc or libc6) 2.13 and earlier does not report an error status for failed attempts to write to the /etc/mtab file, which makes it easier for local users to trigger corruption of this file, as demonstrated by writes from a process with a small RLIMIT_FSIZE value, a different vulnerability than CVE-2010-0296.

redhat
больше 14 лет назад

The addmntent function in the GNU C Library (aka glibc or libc6) 2.13 and earlier does not report an error status for failed attempts to write to the /etc/mtab file, which makes it easier for local users to trigger corruption of this file, as demonstrated by writes from a process with a small RLIMIT_FSIZE value, a different vulnerability than CVE-2010-0296.

nvd
больше 14 лет назад

The addmntent function in the GNU C Library (aka glibc or libc6) 2.13 and earlier does not report an error status for failed attempts to write to the /etc/mtab file, which makes it easier for local users to trigger corruption of this file, as demonstrated by writes from a process with a small RLIMIT_FSIZE value, a different vulnerability than CVE-2010-0296.

debian
больше 14 лет назад

The addmntent function in the GNU C Library (aka glibc or libc6) 2.13 ...

oracle-oval
больше 13 лет назад

ELSA-2011-1526: glibc security, bug fix, and enhancement update (LOW)

EPSS

Процентиль: 26%
0.00087
Низкий